cart-m 0
search-icon
  • Loading...

    Privacy Policy

    Effective Date: 2026-02-27

    TRENVL.COM (the “Company”) establishes and discloses this Privacy Policy as follows in order to protect the personal information of data subjects and to promptly and smoothly handle related grievances in accordance with the Personal Information Protection Act and other applicable laws and regulations.

    1. Purpose of Processing Personal Information, Items Collected, and Retention/Use Period

    The Company processes only the minimum personal information necessary to provide its services and does not use such information for purposes other than those listed below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with applicable laws and regulations.

    A. Membership Registration and Account Management

    - Purpose: Member identification, confirmation of intent to register, identity verification, account management, customer support

    - Items Collected (examples): Name, email address, password, mobile phone number, country, language settings

    - Retention Period: Until membership withdrawal. However, if retention is required by applicable laws, it will be retained for the relevant statutory period

    B. Reservations, Orders, Payments, and Contract Performance

    - Purpose: Reservation receipt, order processing, payment confirmation, voucher issuance, contract performance, refund processing, dispute handling

    - Items Collected (examples): Booker’s name, user’s name, contact information, email, nationality, passport information (if required for overseas travel/flights/accommodations, etc.), date of birth, payment information (payment method details, approval information), usage history

    - Retention Period: Until 5 years after transaction completion or until the end of the statutory retention period under applicable laws

    C. Medical, Beauty, Education, and Personalized Consultation Inquiries

    - Purpose: Receiving consultation requests, partner matching, checking reservation availability, responding to inquiries

    - Items Collected (examples): Name, contact information, email, country, inquiry details, preferred schedule, services of interest

    - Retention Period: 1 year after the consultation is completed. However, if retention is necessary for dispute response or follow-up inquiries, it will be retained for the relevant period

    D. Customer Service, Complaints, and Dispute Resolution

    - Purpose: Complaint handling, fact verification, response to complaints, dispute mediation, legal response

    - Items Collected (examples): Name, contact information, email, order/reservation information, inquiry details, attached materials

    - Retention Period: 3 years after completion of processing or until the end of the statutory retention period under applicable laws

    E. Marketing and Events (Upon Optional Consent)

    - Purpose: Event notifications, provision of discount/promotion information, newsletter delivery

    - Items Collected (examples): Name, email address, mobile phone number, country, categories of interest

    - Retention Period: Until consent is withdrawn

    2. Retention of Personal Information Pursuant to Applicable Laws

    The Company may retain personal information for a certain period as required under applicable laws and regulations, as follows:

    • Records related to contracts or withdrawal of subscription, etc.: 5 years
    • Records related to payment and supply of goods/services: 5 years
    • Records related to consumer complaints or dispute resolution: 3 years
    • Access records (where necessary for service security and verification of communications): For the period required under applicable laws or internal policies

    3. Provision of Personal Information to Third Parties

    The Company processes personal information only within the scope of the purposes described in Section 1 and provides it to third parties only where there is a legal basis under applicable laws, such as the data subject’s consent or special provisions of law.

    Example of Provision

    - Recipient: Reservation partners (hotels, tour operators, hospitals, clinics, educational institutions, carriers, etc.)

    - Purpose: Reservation confirmation, service provision, user identification, schedule coordination, on-site assistance

    - Items Provided: Name, contact information, email, reservation details, service schedule, nationality, passport information (if required)

    - Retention/Use Period: Until completion of service provision and for each partner’s statutory or contractual retention period

    ※ If there are actual recipients, please make sure to specify the name of the recipient or the scope by recipient type in detail according to your actual business operations before publication.

    4. Entrustment of Personal Information Processing

    The Company may outsource personal information processing tasks to external parties in order to provide smooth services. When entering into outsourcing agreements, the Company stipulates necessary matters to ensure the safe processing of personal information in accordance with applicable laws and supervises the entrusted parties.

    Examples of Outsourcing

    - Payment Gateway (PG): Payment approval, payment processing, refund processing

    - Cloud/Hosting: Data storage, server operation, backup

    - SMS/Email Delivery: Authentication, reservation notices, alert delivery

    - Customer Service Solutions: Inquiry reception and consultation support

    - Analytics Tools: Service usage statistics and performance improvement

    ※ In actual operation, please accurately state the names of the entrusted companies (e.g., PG provider, cloud provider, email delivery provider).

    5. Overseas Transfer of Personal Information

    The Company may transfer personal information overseas in the course of providing services, such as reservations with overseas partners, use of global cloud services, and integration with overseas payment or reservation systems. In such cases, the Company will ensure a lawful basis for transfer under applicable laws and disclose the required information in this Privacy Policy.

    Example of Overseas Transfer

    - Recipient: Overseas reservation partners, overseas cloud service providers, overseas payment/reservation system operators

    - Country of Transfer: [e.g., Singapore / United States / Japan / Vietnam — specify the actual country]

    - Items Transferred: Name, contact information, email, reservation details, payment-related information, passport information (if required)

    - Purpose of Transfer: Reservation confirmation, service provision, data storage, system operation

    - Timing and Method of Transfer: At the time of reservation or during service use, via network transmission

    - Retention/Use Period: Until the purpose is achieved or until the end of the retention period required by applicable laws/contracts

    ※ If overseas transfer actually occurs, the country of transfer, recipient, items transferred, purpose, and retention period must be specified in detail according to actual operations.

    6. Procedures and Methods for Destruction of Personal Information

    The Company destroys personal information without delay when the retention period has expired or the processing purpose has been achieved.

    • Electronic files: Deleted using technical methods that make recovery or restoration impossible
    • Paper documents: Shredded or incinerated

    7. Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercising Rights

    Data subjects may exercise the following rights with respect to the Company at any time:

    • Request access to personal information
    • Request correction or deletion of personal information
    • Request suspension of processing of personal information
    • Withdraw consent
    • Refuse receipt of marketing information

    Such rights may be exercised in writing, by email, through customer service, or by other means, and the Company will take action without delay in accordance with applicable laws. A legal representative may exercise these rights on behalf of a child under the age of 14 with respect to the child’s personal information.

    8. Processing of Personal Information of Children Under the Age of 14

    If the Company collects personal information of children under the age of 14, it will take necessary measures, such as obtaining the consent of a legal representative, in accordance with applicable laws. If the service is not intended for children under the age of 14, the Company may, in principle, restrict membership registration or service use by persons in that age group.

    9. Automatically Collected Information and Use of Cookies

    The Company may automatically collect cookies, access logs, device information, browser information, IP addresses, and usage records during the course of service use.

    • Purpose of Collection: Maintaining login sessions, language settings, analyzing usage statistics, improving services, preventing fraudulent use
    • Users may refuse or delete the storage of cookies through browser settings.
    • However, if cookie storage is refused, some services may be restricted.

    10. Measures to Ensure the Security of Personal Information

    The Company takes the following measures to ensure the security of personal information:

    • Minimization of personnel handling personal information and management of access rights
    • Encryption of passwords and other important information
    • Retention of access records and access control
    • Installation and operation of security programs
    • Operation of server and network security measures, backup, and incident response systems

    11. Chief Privacy Officer and Grievance Handling Department

    The Company designates the following Chief Privacy Officer and responsible department to oversee personal information processing, handle complaints from data subjects, and provide remedies for damages.

    Chief Privacy Officer (CPO)

    - Name: [Name of Responsible Person]

    - Title: [Title]

    - Email: [Email]

    - Contact: [Phone Number]

    Personal Information Grievance Handling Department

    - Department: [Customer Service / Operations Team, etc.]

    - Email: [Email]

    - Contact: [Phone Number]

    12. Remedies for Infringement of Rights and Interests of Data Subjects

    Data subjects may contact the following institutions for damage relief or consultation regarding personal information infringement:

    • Personal Information Dispute Mediation Committee
    • Personal Information Infringement Report Center
    • Supreme Prosecutors’ Office
    • National Police Agency Cybercrime Reporting System

    ※ The above institutions are separate from the Company. You may contact them if you are not satisfied with the Company’s own resolution of personal information complaints or damage relief, or if you need more detailed assistance.

    13. Changes to the Privacy Policy

    This Privacy Policy may be changed in accordance with applicable laws, service content, or Company policy. If changes are made, the Company will provide notice through the Site. If there are material changes, the Company will give prior notice for a reasonable period before the effective date.

    [Required Business Information]

    Company Name: ONKO Co., Ltd. / Representative: [Song Sujin] / Business Registration No.: [406-81-67192] /
    Address: Suite 603, Yeongdeungpo D-State, 28 Seonyuseo-ro 25-gil, Yeongdeungpo-gu, Seoul, Republic of Korea
    Main Email: [trenvl@trenvl.com] / Customer Service: [+82-2-6006-0471]

    Privacy Policy

    Effective Date: 2026-02-27

    TRENVL.COM (the “Company”) establishes and discloses this Privacy Policy as follows in order to protect the personal information of data subjects and to promptly and smoothly handle related grievances in accordance with the Personal Information Protection Act and other applicable laws and regulations.

    1. Purpose of Processing Personal Information, Items Collected, and Retention/Use Period

    The Company processes only the minimum personal information necessary to provide its services and does not use such information for purposes other than those listed below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with applicable laws and regulations.

    A. Membership Registration and Account Management

    - Purpose: Member identification, confirmation of intent to register, identity verification, account management, customer support

    - Items Collected (examples): Name, email address, password, mobile phone number, country, language settings

    - Retention Period: Until membership withdrawal. However, if retention is required by applicable laws, it will be retained for the relevant statutory period

    B. Reservations, Orders, Payments, and Contract Performance

    - Purpose: Reservation receipt, order processing, payment confirmation, voucher issuance, contract performance, refund processing, dispute handling

    - Items Collected (examples): Booker’s name, user’s name, contact information, email, nationality, passport information (if required for overseas travel/flights/accommodations, etc.), date of birth, payment information (payment method details, approval information), usage history

    - Retention Period: Until 5 years after transaction completion or until the end of the statutory retention period under applicable laws

    C. Medical, Beauty, Education, and Personalized Consultation Inquiries

    - Purpose: Receiving consultation requests, partner matching, checking reservation availability, responding to inquiries

    - Items Collected (examples): Name, contact information, email, country, inquiry details, preferred schedule, services of interest

    - Retention Period: 1 year after the consultation is completed. However, if retention is necessary for dispute response or follow-up inquiries, it will be retained for the relevant period

    D. Customer Service, Complaints, and Dispute Resolution

    - Purpose: Complaint handling, fact verification, response to complaints, dispute mediation, legal response

    - Items Collected (examples): Name, contact information, email, order/reservation information, inquiry details, attached materials

    - Retention Period: 3 years after completion of processing or until the end of the statutory retention period under applicable laws

    E. Marketing and Events (Upon Optional Consent)

    - Purpose: Event notifications, provision of discount/promotion information, newsletter delivery

    - Items Collected (examples): Name, email address, mobile phone number, country, categories of interest

    - Retention Period: Until consent is withdrawn

    2. Retention of Personal Information Pursuant to Applicable Laws

    The Company may retain personal information for a certain period as required under applicable laws and regulations, as follows:

    • Records related to contracts or withdrawal of subscription, etc.: 5 years
    • Records related to payment and supply of goods/services: 5 years
    • Records related to consumer complaints or dispute resolution: 3 years
    • Access records (where necessary for service security and verification of communications): For the period required under applicable laws or internal policies

    3. Provision of Personal Information to Third Parties

    The Company processes personal information only within the scope of the purposes described in Section 1 and provides it to third parties only where there is a legal basis under applicable laws, such as the data subject’s consent or special provisions of law.

    Example of Provision

    - Recipient: Reservation partners (hotels, tour operators, hospitals, clinics, educational institutions, carriers, etc.)

    - Purpose: Reservation confirmation, service provision, user identification, schedule coordination, on-site assistance

    - Items Provided: Name, contact information, email, reservation details, service schedule, nationality, passport information (if required)

    - Retention/Use Period: Until completion of service provision and for each partner’s statutory or contractual retention period

    ※ If there are actual recipients, please make sure to specify the name of the recipient or the scope by recipient type in detail according to your actual business operations before publication.

    4. Entrustment of Personal Information Processing

    The Company may outsource personal information processing tasks to external parties in order to provide smooth services. When entering into outsourcing agreements, the Company stipulates necessary matters to ensure the safe processing of personal information in accordance with applicable laws and supervises the entrusted parties.

    Examples of Outsourcing

    - Payment Gateway (PG): Payment approval, payment processing, refund processing

    - Cloud/Hosting: Data storage, server operation, backup

    - SMS/Email Delivery: Authentication, reservation notices, alert delivery

    - Customer Service Solutions: Inquiry reception and consultation support

    - Analytics Tools: Service usage statistics and performance improvement

    ※ In actual operation, please accurately state the names of the entrusted companies (e.g., PG provider, cloud provider, email delivery provider).

    5. Overseas Transfer of Personal Information

    The Company may transfer personal information overseas in the course of providing services, such as reservations with overseas partners, use of global cloud services, and integration with overseas payment or reservation systems. In such cases, the Company will ensure a lawful basis for transfer under applicable laws and disclose the required information in this Privacy Policy.

    Example of Overseas Transfer

    - Recipient: Overseas reservation partners, overseas cloud service providers, overseas payment/reservation system operators

    - Country of Transfer: [e.g., Singapore / United States / Japan / Vietnam — specify the actual country]

    - Items Transferred: Name, contact information, email, reservation details, payment-related information, passport information (if required)

    - Purpose of Transfer: Reservation confirmation, service provision, data storage, system operation

    - Timing and Method of Transfer: At the time of reservation or during service use, via network transmission

    - Retention/Use Period: Until the purpose is achieved or until the end of the retention period required by applicable laws/contracts

    ※ If overseas transfer actually occurs, the country of transfer, recipient, items transferred, purpose, and retention period must be specified in detail according to actual operations.

    6. Procedures and Methods for Destruction of Personal Information

    The Company destroys personal information without delay when the retention period has expired or the processing purpose has been achieved.

    • Electronic files: Deleted using technical methods that make recovery or restoration impossible
    • Paper documents: Shredded or incinerated

    7. Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercising Rights

    Data subjects may exercise the following rights with respect to the Company at any time:

    • Request access to personal information
    • Request correction or deletion of personal information
    • Request suspension of processing of personal information
    • Withdraw consent
    • Refuse receipt of marketing information

    Such rights may be exercised in writing, by email, through customer service, or by other means, and the Company will take action without delay in accordance with applicable laws. A legal representative may exercise these rights on behalf of a child under the age of 14 with respect to the child’s personal information.

    8. Processing of Personal Information of Children Under the Age of 14

    If the Company collects personal information of children under the age of 14, it will take necessary measures, such as obtaining the consent of a legal representative, in accordance with applicable laws. If the service is not intended for children under the age of 14, the Company may, in principle, restrict membership registration or service use by persons in that age group.

    9. Automatically Collected Information and Use of Cookies

    The Company may automatically collect cookies, access logs, device information, browser information, IP addresses, and usage records during the course of service use.

    • Purpose of Collection: Maintaining login sessions, language settings, analyzing usage statistics, improving services, preventing fraudulent use
    • Users may refuse or delete the storage of cookies through browser settings.
    • However, if cookie storage is refused, some services may be restricted.

    10. Measures to Ensure the Security of Personal Information

    The Company takes the following measures to ensure the security of personal information:

    • Minimization of personnel handling personal information and management of access rights
    • Encryption of passwords and other important information
    • Retention of access records and access control
    • Installation and operation of security programs
    • Operation of server and network security measures, backup, and incident response systems

    11. Chief Privacy Officer and Grievance Handling Department

    The Company designates the following Chief Privacy Officer and responsible department to oversee personal information processing, handle complaints from data subjects, and provide remedies for damages.

    Chief Privacy Officer (CPO)

    - Name: [Name of Responsible Person]

    - Title: [Title]

    - Email: [Email]

    - Contact: [Phone Number]

    Personal Information Grievance Handling Department

    - Department: [Customer Service / Operations Team, etc.]

    - Email: [Email]

    - Contact: [Phone Number]

    12. Remedies for Infringement of Rights and Interests of Data Subjects

    Data subjects may contact the following institutions for damage relief or consultation regarding personal information infringement:

    • Personal Information Dispute Mediation Committee
    • Personal Information Infringement Report Center
    • Supreme Prosecutors’ Office
    • National Police Agency Cybercrime Reporting System

    ※ The above institutions are separate from the Company. You may contact them if you are not satisfied with the Company’s own resolution of personal information complaints or damage relief, or if you need more detailed assistance.

    13. Changes to the Privacy Policy

    This Privacy Policy may be changed in accordance with applicable laws, service content, or Company policy. If changes are made, the Company will provide notice through the Site. If there are material changes, the Company will give prior notice for a reasonable period before the effective date.

    [Required Business Information]

    Company Name: ONKO Co., Ltd. / Representative: [Song Sujin] / Business Registration No.: [406-81-67192] /
    Address: Suite 603, Yeongdeungpo D-State, 28 Seonyuseo-ro 25-gil, Yeongdeungpo-gu, Seoul, Republic of Korea
    Main Email: [trenvl@trenvl.com] / Customer Service: [+82-2-6006-0471]